NEW YORK STATE SECURITY BREACH REPORTING FORM 
Pursuant to the Information Security Breach and Notification Act 
(General Business Law §899-aa; State Technology Law §208) 


Name and address of Entity that owns or licenses the computerized data that was subject to the breach : 

Imhoff and Associates, RC.___ 

Street Address: _ 12424 Wilshire Blvd ___ 

City: Los A n gelas State: CA Zip Code: 90025 _ 


Submitted by : Tanya Forsheit _ Title: Partner ___Dated: September 29, 2014 

Firm Name (if other than entity): Baker & Hostetler LLP ______ 

Telephone: (310) 442-8831 _Email: tforsheit@bakerlawxom _ 

Relationship to Entity whose information was compromised: Qntsidg Qojinsel 


Type of Organization (please select one): [ ] Governmental Entity in New York State; [ J Other Governmental Entity; 
( J Educational; ( ]Health Care; [ ]Finandal Services; [ X ]Other Commercial; [ ] Not-for-profit 


Number of Persons Affected : 

Total (Including NYS residents): 13 f Q26 NYS Residents: 199 pursuant to NY statute 

If the number of NYS residents exceeds 5,Q00 r have the consumer reporting agencies been notified? [] Yes; [X ] No. 


Dates : Breach Occurred: lune 27.2014 Breach Discovered: tune 27,2014 

Consumer Notification: mailing commenced on August 26,2014, continued through September 26, 2014 


Description of Breach (please select aU that apply): 

[ X - please see attached Appendix ]Loss or theft of device or media (e*g«, computer, laptop, external hard drive, thumb 
drive, CD, tape); 

[ ]Intemal system breach; [ ]lnsider wrongdoing; [ ] External system breach (e.g., hacking); [ jlnadvertent disclosure; 
[ JOther (specify):_ 


Information Acquired : Name or other personal identifier in combination with (please select ^ that apply); 
[XjSocial Security Number 

[XJDriver's license number or non-driver identification card number 

[XJFinandal account number or credit or debit card number, in combination with the security code, access code, 
password, or PIN for the account 


Manner of Notification to Affected Persons - ATTACH A COPY OF THE TEMPLATE OF THE NOTICE TO 
AFFECTED NYS RESIDENTS: 

[ X ] Written; [ ] Electronic; [ ] Telephone; [ ] Substitute notice. 

List dates of any previous (within 12 months) breach notifications: None _ 

Identify Theft Protection Service Offered : [X] Yes; l ] No, 

Duration: One year Provider: AllClear _ 

Brief Description of Service: Credit monitoring and identity theft protection services 
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Appendix 


This letter follows up on my prior correspondence dated August 26, 2014, in which I notified your 
office that our client, Imhoff and Associates, P.C. ("Imhoff"), learned on June 27, 2014, that a hard drive 
containing backup fifes for one of the firm's servers was stolen from the locked trunk of an employee's 
vehicle. 

As a supplement to our initial notification, Imhoff has identified 199 additional New York residents 
who may have been affected by this incident. We still have no reason to believe that the hard drive was 
stolen for the information it contained or that the information has been misused in any way. Still, as a 
precaution, Imhoff began notifying the additional individuals affected by the incident on September 26, 
2014 and is offering them one year of complimentary credit monitoring and identity theft protection 
services through AllClear ID. Imhoff is also providing call center support for those affected. A sample of the 
notification letter sent to the additional affected residents is attached hereto. 
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IMHOFF# 

Associates, pc 

CRIMINAL DEFENSE ATTORNEYS 

Processing Center - P.O. Box 3825 Suwanee, GA 30024 


John Q. Sample September 26, 2014 

823 Congress Ave. 

Ste. 300 

Austin, TX 78701 


Dear John Q. Sample, 

Imhoff and Associates, PC is writing to inform you of an incident that may have involved some of your confidential 
information and the steps we have taken to minimize its impact on you. 

What happened? 

On June 27, 2014, a hard drive containing backup files for one of the firm's servers, along with other incidental items, was 
stolen from the locked trunk of an employee's vehicle. The stolen items included loose change, cufflinks, a tire pressure gauge, 
a Timex watch and the above-referenced hard drive. At this time, we have no reason to believe that the hard drive was stolen for 
the information that it contained or that the information has been misused in anyway. The theft was immediately reported to the 
Santa Monica Police Department. 

We sincerely regret any inconvenience or concern caused by this incident and we have taken steps to help prevent any 
reoccurrence. 

The hard drive may have contained the following information: your name, birthday. Social Security number, driver's license 
number, and contact information, such as your home address, e-mail and phone number, as well as other information relating to 
legal matters handled by our firm. The hard drive was not encrypted, but special software would be required to read most of 
information that may have been contained on the hard drive and the thief did not take such software. 

What did Imhoff & Associates, PC do to protect me? 

As a precaution, we have arranged to have AllClear ID help you protect your identity for 12 months at no cost to you. The 
following identity protection services will be available to you beginning on the date of this letter, and you can use them at any 
time during the next 12 months. 

AllClear SECURE: The team at AllClear ID is ready to work with you to protect your identity. Because you are receiving this 
letter, you are eligible to use the AllClear SECURE service if you so choose. If a problem arises, simply call 1 -877-615-3769 
and a dedicated investigator will assist you in attempting to recover financial losses and take steps to help restore your credit 
and identity to their proper condition. AllClear maintains an AT rating at the Better Business Bureau. 

AllClear PRO: This service offers you additional layers of protection including credit monitoring and a $1 million identity theft 
insurance policy. If you would like to use the AllClear PRO service, you will need to provide your personal information to 
AllClear ID. You may sign up for the AllClear PRO service online at enroll.allclearid.com or by phone by calling 1 -877-615- 
3769 using the following redemption code: 999999999, 

Please note: Additional steps may be required by you in order to activate your phone alerts. 

We also recommend that you carefully check your credit reports for accounts you did not open or for inquiries from creditors 
you did not initiate. If you see anything you do not understand, call the credit agency immediately. If you find any suspicious 
activity on your credit reports, call the police. Also, please review the enclosed "Information about Identity Theft Protection" 
reference guide on the back of this letter, which describes additional steps you can take to help protect yourself, including 
recommendations by the Federal Trade Commission regarding identity theft protection and details on how to place a fraud alert 
or a security' freeze on your credit file. 


' MOHi-'I 
•/i.-.ii 7. no- / 

;j ” .T l *, *;,l - 

I ► :v, - 4 . ' I I IS PtH 


* i 'rcdfin’cpft .0 Aitr I 

:w Wiijnoi - 

0<V 

*OVH r r T .nifiW 


. jb t S& <*J nrfot JiO* : 

i *4jov V ‘S b^^fjvii j rr,f( /i»*rj iurfr imbbni nti » imon ni ,<nijnw m T! wltizo ti tm Tu-H/ctl 

,i a r» i i6f|iUi /*: : j;ttimiTf oi 'laJftl * "iff ?v/ ; f]5i ‘iffc ! *i Aoil T Ini 

ttaw#(jqi:il f«fttW 

vnw .-, • ■«. 1 ■. j/iOk ^ifnr jfh . ->r. ? •««*! I * *4. : riv< u*j ; f iiiud c . ►•: iJE t ££ » >ul it * 

: - ■ i 1 V ■Of»| t* jtiwK ii n* rfi'j ‘ >rfj 'J r ;■ '• •iV*’ -fit. , | f >i t tjo4:>of adi ro■ tl no^iK: 

HI i ■ „ i . . .. tvi/do adj bn* dots//xarntT c 

b*lv> * /I * r,ir. 1 >'/n1 / u * b';* v i> H ictf ' 4leun< i nt wit u d a oniono'j U >b? vift 

Inwnh^^'jQ 1 v:..if*4 sttu,/ 

' " f jft «I3 ■ »/.. 2 ^ - l HI ffj ■ ■ . ! 

, s luttusn 


■4 :*. ' ■ :»v i.i - ;n /• j/ Ii. x/f rul.in^l .v i • > Mtk«J s:! ? b tiiwW. ava.1 ^ 3 .4 * mi 3<<X 

i- 5 a- 4 :.’ fr«ji t*fr ■•■ * . .. * i* •-.- ._i, i m - 1 , : .m b;ii, m. #nbbfl ?r* m// '7 f : i ’ .:* • ‘-.if. ■ *• .. i V * 

t om 4 , /I ?n. > •*•-« : * '• / 't.' MV *»’■' ;iffv 1 4i\\t : n m . i L’r/» till rris • M tt*S; n 

. 4 iLu* r2i:i f f t> ■ ' :' ’uii bfJFt ‘ nl bltfl ’* :• m f im») y/i>-. ■ fLfli *lt>i^" f ’ till 

7j!'? J Ji Ivi <M Jtv* <F»I f'! itrf// 

Hi'1 '*/ : i f J on Ic afl. n I J /:: 1 : ./.I ,im-/ ;/iKil«{ . , { q'vi! * [I i,r ► 'V*h vti .•; ii/ wu! 5 - iCtM/T IM", ., f 

%... :rl UK...: .if I ■ ,. . V m u .Mil 1 99f»U b.lJ f V» !><•/ Ol )*!.«' **'. *i 'Ji * r »t ohj’i.Mq gtl' Ut 

• ftlritjffi Cl 1/^n 3fb UJtiw\ if'til 

■a giii im moov u.- v: ■. tuovf^i K| or ho^ iftlw ihow oa ai QU >*. i 

1 ' ■ ■ K rf ■ 1 . 

lib ; 3 . - s 1 i* Jl* '■ l m-: 1 !}f»i! li !• - -r* > ■ - l 1 f^r, r» , v Hr// ' ' .* /i J . bfi 1 . 

'■ * U ^ ; m nn , • ,.• 1 ni-'.itirfloQ >£* /* **fJ #. -> n^i bni; 

ME' , /t-ibi r I : * . l-rtf ■' Mi r' ;•• - MM Vi >'iq b ' .he if ' . r'rf ( :i M /: 

at n immcftif Iiifi< kj hh ■ ■ iq o ' ... * • -m ^ ■■■ HI/ ■ ■ tfjlli bit w ua^ tl s^wmitn 

|f#iil rnoo.biiwIolUJIcrtoo )c ^ni 1 * M rA ftM Ofl'l waf HiA ftrii Kj? qu nv. ’ ^ UoY €JI )ll> 

j 1 orjqmvl'Vi .vHm Tfft ai. >u t*<>T 

it nt !'/ ^i.v/KafMji ,j , ■ • vd bt’iijp'ji i/n fit t q‘j ‘i.m* .. *i;or . h - ir 

■ ; j ■ • •' • 

■- f 1 *:. *!. .. v> r ' . /tifijq,, iuMi-' . : Ur. - v • ,.»#■ i‘jb* - ■; ^ ■■ ’ ,..*j v*» : ; : ! • ■" • - •• 

bo (bwaivo m ■ h I 1 r : A Hit <■ <« i lib a itse , 

• Mrta -fi ii-jp i /for, -Jvri oi o:4r^ i«>t sq W’JiUu >v :DVnob rfjiriv j ;h* to U-isd * it ?: ■§ rjtn'U. 

b bui:4 * t*t v -it : . rjyb* 4 ' ^ rr ; - ijinbl f b m it ■- » *.vjcm' vI >:T ft.f: . •.«*• 

•jffl lilJO1i;0< O /V £ *f 




NEW YORK STATE SECURITY BREACH REPORTING FORM 

Pursuant to the Information Security Breach and Notification Act 
(General Business Law §899-aa; State Technology Law §208) 


Name and address of Entity that owns or licenses the computerized data that was subject to the breach : 

Imhoff and Associates, P.C. ____ 

Street Address: — 12424 Wiltshire Blvd ___ 

City: Los Angeles ____ State: CA Zip Code: 90025 _ 


Submitted by : Tanya Forsheit _ Title: Partner __ Dated: August 26, 2014 

Firm Name (if other than entity): Baker & Hostetler LLP _ 

Te lephone: (310) 442-8831 _Emai 1: tforshei bakerlaw. com __ 

Relationship to Entity whose information was compromised: Outside Counsel 


Type of Organization (please select one): | ] Governmental Entity in New York State; ( ] Other Governmental Entity-; 
[ ] Educational; [ ]Health Care; 1 ]Financial Services, [ X ]Other Commercial; [ | Not-for-profit 


Number of Persons Affected : 

Total (Including NYS residents): 1967 NYS Residents: 53 pursuant to NY statute 

If the number of NYS residents exceeds 5,000, have the consumer reporting agencies been notified? 11 Yes; [ X ] No. 


Dates Breach Occurred: fune 27, 2014 Breach Discovered: lone 27, 2014 
Consumer Notification: mailing commenced on August 26, 2014 


Description of Breach (please select idi that apply): 

[ X - please see attached Appendix [Loss or theft of device or media (e,g„ computer, laptop, external hard drive, thumb 
drive, CD, tape); 

[ |Internal system breach; | ]Insider wrongdoing; | ]External system breach (e.g., hacking); [ ]Inadvertent disclosure; 
[ JOthcr (specify):____ 


Information Acquired : Name or other personal identifier in combination with (please select ^L! that apply): 

[ XfSocial Security Number 

[ X ]Driver's license number or non-driver identification card number 

[ ]Financial account number or credit or debit card number, in combination with the security code, access code, 
password, or PIN for the account 


Manner of Notification to Affected Persons - ATTACH A COPY OF THE TEMPLATE OF THE NOTICE TO 
AFFECTED NYS RESIDENTS: 

[ X ] Written; [ ] Electronic; ( ] Telephone; [ ] Substitute notice. 

List dates of any previous (within 12 months) breach notifications: None __ 


Identify Theft Protection Service Offered : [X] Yes; [ | No. 

Duration: One year Provider: AUClear ID _ 

Brief Description of Service: Credit monitoring and identity theft protection services 











































Appendix 


Our client, imhoff and Associates, P.C. ("Imhoff"), learned on June 27, 2014, that a hard 
drive containing backup tiles for one of the firm’s servers was stolen from the locked trunk of an 
employee’s vehicle. Imhoff immediately notified the Santa Monica Police Department and began a 
thorough internal investigation to determine what information was contained on the hard drive. 

After a detailed review with outside computer forensic experts, Imhoff confirmed that the 
hard drive may have contained tiles with differing amounts of employee and client information, 
including name. Social Security number, driver’s license number and contact information (e.g., 
email address, mailing address and phone number). Imhoff has been working with law enforcement, 
but to date, has been unable to locate the hard drive. 

Imhoff has no reason to believe that the hard drive was stolen for the information it 
contained or that the information has been misused in any way. Although the hard drive was not 
encrypted, special software would be required in order to read most of the information on the hard 
drive. Still, as a precaution. Imhoff will begin notifying individuals affected by the incident on 
August 26, 2014 and is offering them one year of complimentary credit monitoring and identity theft 
protection services through AllClear. Imhoff is also providing call center support for those affected. 

To help prevent something like this from happening in the future, Imhoff is strengthening its 
encryption processes and enhancing its policies, procedures and staff education regarding the 
safeguarding of firm property and information. 


IMHOFF & 

Associates, pc 

CRIMINAL DEFENSE ATTORNEYS 
Processing Center P O Box 3825 Suwanee, GA 30024 



John 0 Sample 
123 Main Street 
Anytown, US 12345-6789 


August 26, 2014 


Dear John Q Sample: 

ImhofT and Associates, PC (“InihofT 1 ) is writing to inform you of an incident involving a theft of a backup hard 
drive that may have contained some of your information. 

Whar happened? 

During the early morning hours on June 27, 2014, a hard drive containing backup Hies for one of the firm's servers 
was stolen from the locked trunk of an employee's vehicle. The employee discovered the theft later that day and 
immediately notified the Santa Monica Police Department. We have been working with law- enforcement but, to 
date, they have been unable to locate the stolen hard drive. 

ImhofT also immediately began an internal investigation to determine what information was contained on the hard 
drive. Working with outside computer forensic experts, we have confirmed that the hard drive may have contained 
your name, birthday, Social Security number, driver's license number, and contact information, such as your home 
address, e-mail and phone number. 

What is Imhoff and Associates doing to protect me? 

ImhofT has no reason to believe that the hard drive was stolen for the information it contained or that your 
information has been accessed or used in any way. However, as a precaution, wc have arranged to have AllClcar ID 
help you protect your identity for 12 months at no cost to you, The following identity protection services will be 
available to you beginning on the date of this notice, and you can use them at any time during the next 12 months. 

AllClcar SECURE: The team at AllClcar ID is ready to work with you to protect your identity. Because you are 
receiving this letter, you arc eligible to use the AllClcar SECURE service if you so choose. If a problem arises, 
simply call (877) 615-3769 and a dedicated investigator wi ll assist you in attempting to recover financial losses and 
take steps to help restore your credit and identity to their proper condition. AllClcar maintains an A+ rating at the 
Better Business Bureau. 

AllClcar PRO: This service offers you additional layers of protection including credit monitoring and a SI million 
identity theft insurance policy. If you would like to use the AllClcar PRO service, you will need to provide your 
personal information to AllClcar ID. You may sign up for the AUCIear PRO service online at enrolLalldearid.com 
or by phone by calling (877) 615-3769 using the following redemption code: 9999999999. 

Please note: Additional steps may be required by you in order to activate your phone alerts. 

Wc also recommend that you carefully check your credit reports for accounts you did not open or for inquiries from 
creditors you did not initiate. If you see anything you do not understand, call the credit agency immediately. If you 
find any suspicious activity on your credit reports, call the police. Also, please review the enclosed "Information 




about Identity Theft Protection" reference guide on the back of this letter, which describes additional steps you can 
take to help protect yourself, including recommendations by the Federal Trade Commission regarding identity theft 
protection and details on how to place a fraud alert or a security freeze on your credit file. 

What is [rnhoff and Associates doing to prevent this from happening in the future? 

To help prevent something like this from happening in the future, we are strengthening our internal processes with 
respect to encryption and enhancing our policies, procedures and staff education regarding the safeguarding of 
company property and information. 

If you have further questions or concerns about this incident, please call (877) 615-3769. Monday through Saturday, 
8:00 a.m, to 8:00 p.m. Central Standard Time (closed on ITS. observed holidays). We sincerely regret any 
inconvenience or concern caused by this incident. 


Sincerely, 



Vincent M Imhoff 
Managing Director 
Imhoff & Associates, PC 


